Full Disclosure mailing list archives

Re: analysis (more worms wanted :) )


From: "Byron L. Sonne" <blsonne () rogers com>
Date: Tue, 08 Jun 2004 23:09:02 -0400


So far I have analyzed the executables (or scripts) of worms, where
my aim was to determine the familiy of an unknown worm.
You can view some pictures at http://www.cwi.nl/~wehner/worms, where
you can also find more information about the approach I used.
Note that this is *work in progress*.

Regardless, it is still very interesting! Granted my knowledge of the mathematics behind it is certainly sub-optimal, but I believe I can see where you're going. Could you perhaps show some code and the actual mechanics of the math behind it... sometimes the practical helps me understand the theoretical that much better.

I knew there were reasons I stay subscribed to this list... thanks for reminding me ;)

--

For Good, return Good. For Evil, return Justice.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: